<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p>Matt,</p>
<p><br>
</p>
<p>I see nothing obviously wrong with your metadata, but I might not be looking closely enough.</p>
<p><br>
</p>
<p>The bigger problem is that TestShib is still running very old software and the volunteer primarily maintaining it today is overloaded.</p>
<p><br>
</p>
<p>Have you tested loading the metadata in other providers?</p>
<p><br>
</p>
<p>Sorry to not be more useful,</p>
<p>Nate.<br>
</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Matt Self <matt@crafted.education><br>
<b>Sent:</b> Thursday, July 27, 2017 4:50:31 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> testshib IDP not finding config so "unable to select endpoint"</font>
<div> </div>
</div>
<div>
<div dir="ltr"><span style="font-size:12.8px">Hi,</span>
<div style="font-size:12.8px">I've setup an app to act as a Service Provider on <a href="http://testshib.org/" target="_blank">testshib.org</a>. I've uploaded my metadata (which afaik looks fine when compared against others and i see no errors in logs when
uploading). And I see my EntityID at <a href="http://www.testshib.org/entities.html" target="_blank">http://www.testshib.org/<wbr>entities.html</a> (EntityID <a href="https://preprod.inscribe.education/organizations/indianau/saml/metadata" target="_blank">https://preprod.inscribe.<wbr>education/organizations/<wbr>indianau/saml/metadata</a>)</div>
<div style="font-size:12.8px"><br>
</div>
<div style="font-size:12.8px">But when sending over an AuthnRequest I get "No peer endpoint available to which to send SAML response". This appears to be because the <span style="color:rgb(0,0,0);white-space:pre-wrap">SAMLMDRelyingPartyConfigur<wbr>ationManager
can't find my configuration by the entityID which I pass in (on the querystring of the request as "providerId" which I send to
</span><font color="#000000"><span style="white-space:pre-wrap"><a href="https://idp.testshib.org/idp/profile/Shibboleth/SSO" target="_blank">https://idp.testshib.org/idp/<wbr>profile/Shibboleth/SSO</a></span></font><span style="color:rgb(0,0,0);white-space:pre-wrap">).
I've confirmed that the entityID in my metadata and matches what I send in providerId. Also, the AssertionConsumerServiceUrl matches in both the metadata and the AuthnRequest. I'm at a loss as to what to look at next.</span></div>
<div style="font-size:12.8px">
<div><br>
</div>
<div>The logs show it falling back to "default" relying party config at which point it isn't going to work:</div>
<div>
<pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word">19:14:58.385 - DEBUG [edu.internet2.middleware.<wbr>shibboleth.common.<wbr>relyingparty.provider.<wbr>SAMLMDRelyingPartyConfiguratio<wbr>nManager:128] - Looking up relying party configuration for <a href="https://preprod.inscribe.education/organizations/indianau/saml/metadata" target="_blank">https://preprod.inscribe.<wbr>education/organizations/<wbr>indianau/saml/metadata</a>
19:14:58.385 - DEBUG [edu.internet2.middleware.<wbr>shibboleth.common.<wbr>relyingparty.provider.<wbr>SAMLMDRelyingPartyConfiguratio<wbr>nManager:134] - No custom relying party configuration found for <a href="https://preprod.inscribe.education/organizations/indianau/saml/metadata" target="_blank">https://preprod.inscribe.<wbr>education/organizations/<wbr>indianau/saml/metadata</a>, looking up configuration based on metadata groups.
19:14:58.386 - DEBUG [edu.internet2.middleware.<wbr>shibboleth.common.<wbr>relyingparty.provider.<wbr>SAMLMDRelyingPartyConfiguratio<wbr>nManager:157] - No custom or group-based relying party configuration found for <a href="https://preprod.inscribe.education/organizations/indianau/saml/metadata" target="_blank">https://preprod.inscribe.<wbr>education/organizations/<wbr>indianau/saml/metadata</a>. Using default relying party configuration.
19:14:58.386 - DEBUG [edu.internet2.middleware.<wbr>shibboleth.idp.profile.saml1.<wbr>ShibbolethSSOEndpointSelector:<wbr>62] - Unable to select endpoint, no entity role metadata available.
19:14:58.387 - ERROR [edu.internet2.middleware.<wbr>shibboleth.idp.profile.<wbr>AbstractSAMLProfileHandler:<wbr>447] - No return endpoint available for relying party <a href="https://preprod.inscribe.education/organizations/indianau/saml/metadata" target="_blank">https://preprod.inscribe.<wbr>education/organizations/<wbr>indianau/saml/metadata</a></pre>
</div>
<div><br>
</div>
<div>I've attached my metadata xml and an example authnrequest.xml.</div>
<div><br>
</div>
<div>Any help is greatly appreciated. </div>
<div>Thanks so much.</div>
</div>
<div>Matt Self</div>
</div>
</div>
</body>
</html>